EirMed Devices, part of TRELLEBORG Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The EirMed Devices, part of TRELLEBORG Listed by alphv Ransomware Group (reported May 2, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a company that designs and builds medical devices appears on a ransomware group's leak site, the people who may feel it first are not executives or engineers but patients, staff, suppliers and partners whose details could sit inside internal systems. On 2 May 2023, EirMed Devices, part of TRELLEBORG, was listed by the alphv ransomware group, which claimed that internal files had been taken in a ransomware attack. The number of people affected remains unknown, and public detail about exactly what left the network is limited. For anyone who has dealt with the firm or its parent, that uncertainty is itself the practical stake: without clear confirmation of what was copied, the sensible response is caution rather than panic.
This article sets out only what has been reported, places the claim in the context of how alphv typically operates, and explains why a breach at a medical-device manufacturer matters even when the full inventory of stolen data has not been published.
Breaking down the breach
According to the available record, EirMed Devices, part of TRELLEBORG, was listed by the alphv ransomware group on or around 2 May 2023. The group’s claim is that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of people affected. No detailed inventory of file names, databases or record counts has been released in the material provided. The method of initial access, the duration of any intrusion, and whether systems were encrypted as well as copied are all undisclosed.
What is stated is straightforward: the organisation was named on the group’s leak site in connection with a ransomware incident involving the theft of internal files. Beyond that listing and the characterisation of the data as internal files, further technical or operational detail has not been made public in the facts at hand. Readers should therefore treat the scale and precise contents of the incident as unconfirmed.
Who is alphv?
Alphv, also widely known in security reporting as BlackCat, is a ransomware operation that emerged in late 2021 and became one of the more prominent ransomware-as-a-service groups of the following years. It has typically offered affiliates a customisable ransomware strain written in Rust, used double-extortion tactics—encrypting systems while also stealing data and threatening to publish it—and maintained a dark-web leak site where victims are named if negotiations stall. The group has been linked in public reporting to attacks across multiple sectors, including manufacturing, healthcare-adjacent firms and professional services, often demanding large ransoms and releasing samples or full archives when unpaid.
Like other ransomware crews of its type, alphv’s public listings are claims made by the attackers themselves. They are not independent confirmations of every detail. In this case, the facts record that EirMed Devices, part of TRELLEBORG, was listed and that the group asserted internal files had been exfiltrated; they do not independently verify the volume, sensitivity or full scope of any stolen material. Security researchers and law-enforcement agencies have tracked alphv’s activity for years, and the group’s infrastructure and branding have been disrupted at various points, but those broader developments do not alter the limited public record of this specific listing.
Who is EirMed Devices, part of TRELLEBORG?
EirMed is described as a leader in the design, engineering, manufacturing, assembly and packaging of medical devices, with expertise applied to devices intended to improve patients’ lives. It forms part of TRELLEBORG, a larger industrial group. Organisations in this sector typically sit at the intersection of engineering, regulated manufacturing and healthcare supply chains. They handle product designs, quality and regulatory documentation, supplier and customer records, and often personal data relating to employees and business contacts.
A breach affecting such a firm is consequential because medical-device makers operate under strict quality and traceability expectations. Compromised internal files can touch intellectual property, production processes, commercial relationships and, depending on what is held, information about people who work for or with the company. Even when patient clinical data is not the primary asset, the trust and continuity required in the medical-device supply chain mean that any confirmed or claimed data theft draws attention from partners, regulators and individuals who may have reason to believe their details were stored there.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as whether the files included employee records, customer lists, design documents, financial data or correspondence—has been disclosed in the available record. The number of people affected is unknown.
Companies that design and manufacture medical devices commonly hold engineering drawings and specifications, quality-management and regulatory files, supplier and customer contracts, and ordinary business personal data such as staff names, contact details and HR-related information. Some may also retain limited information linked to clinical or validation work. None of that typical profile should be read as a confirmed inventory of what alphv claims to have taken from EirMed. The exact contents remain unconfirmed; only the broad description of internal files is stated.
The real-world impact
For individuals, the practical risks depend entirely on what was actually copied—something not established in public detail. If employee or contact data were among the internal files, possible consequences include targeted phishing, social-engineering attempts that reference the company, or misuse of names and email addresses. If commercial or technical documents were taken, the harm is more organisational: competitive exposure, strained supplier relationships, or the need to review and re-secure processes. Because the people-affected count is unknown and the file types are not itemised, no one outside the investigation can yet say how widely those risks apply.
For EirMed and TRELLEBORG, a ransomware claim of this kind typically triggers internal investigation, notification assessments under applicable privacy and sector rules, and communication with partners who rely on the integrity of the medical-device supply chain. The listing itself can create reputational and operational pressure even before any data is published or verified. None of this establishes negligence; it simply describes the ordinary consequences that follow when a ransomware group publicly names a manufacturer in this sector.
What to do if you're exposed
If you have worked for, supplied, or otherwise shared personal information with EirMed Devices or related TRELLEBORG entities, treat the situation as a prompt for ordinary hygiene rather than proof that your data was taken. Watch for unexpected emails or calls that reference the company or medical-device work; verify any such contact through known official channels. Consider changing passwords on accounts that used the same or similar credentials as any work-related login, and enable multi-factor authentication where it is available. If you receive notices from the company or from regulators, follow the specific guidance they provide.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or deny involvement in this particular incident, but it can show whether your address is circulating more widely and help you prioritise further protections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Wesgar Inc Listed by alphv Ransomware GroupAura Engineering, LLC Listed by alphv Ransomware GroupDörr Group Listed by alphv Ransomware GroupFischione Instruments Inc Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.